CVE-2025-23006
CRITICAL CISA KEVDescription
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
Is your site exposed to CVE-2025-23006?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sonicwall | sma8200v |
| sonicwall | sma6200_firmware |
| sonicwall | sma6200 |
| sonicwall | sma6210_firmware |
| sonicwall | sma6210 |
| sonicwall | sma7200_firmware |
| sonicwall | sma7200 |
| sonicwall | sma7210_firmware |
| sonicwall | sma7210 |
| sonicwall | sra_ex6000_firmware |
| sonicwall | sra_ex6000 |
| sonicwall | sra_ex7000_firmware |
| sonicwall | sra_ex7000 |
| sonicwall | sra_ex9000_firmware |
| sonicwall | sra_ex9000 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-23006? +
How severe is CVE-2025-23006? +
What products are affected by CVE-2025-23006? +
How do I check if I'm vulnerable to CVE-2025-23006? +
Related Vulnerabilities
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands …
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may …
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI …
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in …
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize …
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite …